Q1. You have a client computer named Computer1 that runs Windows 8 Enterprise. Computer1 has a Trusted Platform Module (TPM) chip installed and the operating system volume is encrypted by using BitLocker Drive Encryption (BitLocker).
You plan to upgrade the BIOS of Computer1.
You need to recommend a solution that meets the following requirements:
Ensures that the drive remains encrypted
Avoids the need to perform a BitLocker recovery
Ensures that Windows can start after the BIOS is upgraded
Minimizes the time required to complete the BIOS upgrade
What should you include in the recommendation?
A. From the command prompt, run manage-bde and specify the -protectors parameter and the -disable parameter.
B. From the command prompt, run manage-bde and specify the -protectors parameter and the -delete parameter.
C. From the Trusted Platform Module (TPM) Management console, click Turn TPM Off from the Actions menu.
D. From the command prompt, run tpmvscmgr.exe and specify the destroy parameter.
Answer: A
Q2. Your network contains a wireless network access point that uses 802.IX certificate-based authentication.
You purchase several devices that run Windows RT.
You need to ensure that the Windows RT devices can authenticate to the wireless access point.
What should you do first?
A. Add a certificate to the Trusted Devices certificate store of the user.
B. Add a certificate to the Trusted Root Certification Authorities certificate store of the computer.
C. Add a certificate to the Trusted Root Certification Authorities certificate store of the user.
D. Add a certificate to the Trusted Devices certificate store of the computer.
Answer: B
Q3. Your network contains an Active Directory domain. The domain contains 100 Windows 8.1 client computers. All of the computers secure all connections to computers on the internal network by using IPSec.
The network contains a server that runs a legacy application. The server does NOT support IPSec.
You need to ensure that some of the Windows 8 computers can connect to the legacy server. The solution must ensure that all other connections are secured by using IPSec.
What should you do?
A. Modify the settings of the Domain Profile.
B. Create a connection security rule.
C. Create an inbound firewall rule.
D. Modify the settings of the Private Profile,
Answer: A
Q4. You administer Windows 8.1 Enterprise computers in an Active Directory domain. Your company has purchased a subscription to Windows Intune. You are assigned as a Global Administrator for Intune.
You determine that a company employee who works at the help desk requires the following permissions:
. Manage support tickets
. Manage subscriptions
You need to assign the appropriate administrative role to the employee.
Which role should you assign to the help desk employee?
A. User Management Administrator
B. Password Administrator
C. Billing Administrator
D. Service Administrator
Answer: D
Q5. You administer computers that run Windows 8 Enterprise and are members of an Active Directory domain.
Some volumes on the computers are encrypted with BitLocker. The BitLocker recovery passwords are stored in Active Directory. A user forgets the BitLocker password to local drive E: and is unable to access the protected volume.
You need to provide a BitLocker recovery key to unlock the protected volume.
Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)
A. Ask the user to run the manage-bde -protectors -disable e: command.
B. Ask the user for a recovery key ID for the protected drive.
C. Ask the user for his or her logon name.
D. Ask the user for his or her computer name.
Answer: B,D
Q6. You have 100 Windows 8.1 client computers.
You plan to purchase a USB device for each computer. The driver for the USB device is unavailable in the Windows driver store. The hardware manufacturer of the USB device provides you with a signed driver for the
device,
You need to ensure that when the new USB device is connected to a computer, the driver
is installed automatically without any user intervention.
What should you run?
A. the dism.exe command
B. the Add-WindowsPackage cmdlet
C. the pnputil.exe command
D. the Add-WindowsDriver cmdlet
Answer: D
Q7. HOTSPOT
Your network contains an Active Directory domain. All client computers run Windows 8
Enterprise and are located in an organizational unit (OU) named Windows8Computers.
The network has Windows Server update Services (WSUS) installed. All of the computers are configured to receive updates from WSUS.
The network administrator creates a new computer group named Win8Computers in WSUS.
You need to ensure that the Windows 8 computers receive all of the updates that are assigned to the WinSComputers computer group.
Which Group Policy setting should you configure? (To answer, select the appropriate setting in the answer area.)
Answer:
Q8. You administer computers that run Windows 8 Enterprise. The computers are members of an Active Directory domain.
You have a tablet that runs Windows 8 Enterprise. You configure the tablet to access your company network by using a virtual private network (VPN) connection.
You need to manage Active Directory from the tablet by using a VPN connection.
What should you do?
A. Run the winrm.exe qc command.
B. Install the System Center Configuration Manager (SCCM) 2012 client.
C. Install the Remote Server Administration Tools (RSAT).
D. Install the Windows Intune client.
Answer: C
Q9. Your network contains an Active Directory domain. The domain contains client computers that run Windows 8 Enterprise.
Users frequently use USB drives to store sensitive files that are used on multiple computers.
Your corporate security policy states that all removable storage devices, such as USB data drives, must be encrypted.
You need to ensure that if a user forgets the password for a USB disk that is encrypted by using BitLocker To Go, the user can resolve the issue them self.
What should you do?
A. Instruct the user to open BitLocker Drive Encryption, select Backup Recovery Key, and then select Save to your Microsoft account.
B. For each computer, create a USB startup key.
C. Instruct the user to open BitLocker Drive Encryption, select Backup Recovery Key, and then select Print the recovery key.
D. From an elevated command prompt, run Manage-BDE -ForceRecovery.
Answer: C
Q10. You support tablets that run Windows 8 Pro. You are designing a remote access server (RAS) that will be placed behind a firewall. The firewall will accept incoming TCP connections to ports 80 and 443 only.
You want to connect to the RAS server from a tablet.
You need to create a virtual private network (VPN) connection to the RAS server.
Which VPN tunneling protocol should you use?
A. IPSec/L2TP
B. SSTP
C. PPTP
D. IPSec/IKEv2
Answer: B